Planning ahead for your GitHub accounts

Lifetime transfer options and steps to take now for GitHub, Inc. (Microsoft) accounts

GitHub, Inc. (Microsoft)

Developer & Cloud

github.com
GitHub, Inc. (Microsoft) logo

GitHub Support

GitHub Deceased User Policy

Verified Jul 2026

GitHub, Inc. (Microsoft) does not guarantee transfer of accounts after death. Lifetime planning provides options for managing accounts and controlling who has access to them.

How to protect your GitHub accounts

8 lifetime planning steps for your GitHub accounts:

1
Designate a successor in Settings > Account > Successor settings (https://github.com/settings/account). The invited user must have a GitHub account and will appear as "Pending" until they accept. This is the single most important step for any active GitHub user; without a successor, the estate must request action case-by-case through the Deceased User Policy.
2
Move critical code into a GitHub Organization and ensure the organization has at least two owners. Successors cannot access private repositories on a personal account, and organizations with only one owner can become orphaned if that owner dies. Promote a trusted collaborator to owner status now.
3
Clone all important repositories locally and back up to external storage. Git repositories are self-contained and can be pushed to any other hosting service (GitLab, Bitbucket, self-hosted Gitea). This provides a recovery path that does not depend on GitHub granting account access.
4
Document the GitHub account username, the email address associated with the account, and the recovery method (authenticator app, hardware key, SMS number) in your digital asset inventory so your executor can attempt sign-in or recovery before invoking the Deceased User Policy.
5
For GitHub Pages sites, keep the source repository inside an Organization where other members have commit access. Pages are served from repositories, so if a personal account is deleted and its repositories go with it, the Pages site also goes offline.
6
Push all work from Codespaces to repositories regularly. Codespaces auto-delete after 30 days of inactivity by default, and GitHub retains a Codespace for only 7 days after a user loses access to it. Uncommitted work is permanently lost.
7
If you receive money through GitHub Sponsors, keep records of Stripe payout history and any accrued unpaid balance. There is no automated succession for Sponsors payouts; the estate will need to work with GitHub Support and Stripe to resolve outstanding amounts.
8
Revoke or rotate personal access tokens, OAuth apps, and SSH/GPG keys periodically, and document which tokens power critical automations so the estate can disable or replace them before billing or security issues compound.

Family sharing

GitHub Successor Settings (https://github.com/settings/account) lets a member designate another GitHub user as their successor. The invited successor must accept the invitation and appears as "Pending" until they do. After the member's death, the successor presents either a death certificate (7-day waiting period) or an obituary (21-day waiting period) to GitHub Support, and can then archive public repositories or transfer them to their own account or to an organization. For Organizations, GitHub recommends maintaining at least two owners at all times so the organization can be administered if one owner dies. Organization owners have complete administrative access; billing managers can manage payment but not repositories; members have default non-admin access. Repository-level roles (Read, Triage, Write, Maintain, Admin) provide granular collaborator access during life.

Should you save your passwords for your family?

Some people store account passwords so a family member can sign in later. The practice has three practical limits:

  • Two-factor authentication often blocks it. Most accounts require a second factor — a code sent to a phone, an authenticator app, a passkey, or a physical key. A saved password alone frequently does not grant access, and the recovery codes that would are easy to lose or let go stale.
  • It usually conflicts with the platform's terms. Most operators prohibit account sharing and signing in as another person, including after a death. Stored credentials are not the operator's recognized access path, and using them can violate the terms of service.
  • Operators provide other paths. Where an operator offers a designation tool — Apple's Legacy Contact, Google's Inactive Account Manager, a beneficiary designation — that mechanism grants access the operator recognizes. A password manager's own emergency-access or legacy feature passes credentials through a controlled process. Digital assets named in a will or trust give a fiduciary authority under each state's Revised Uniform Fiduciary Access to Digital Assets Act (RUFADAA).

Recording that a GitHub account exists, alongside other accounts, gives a fiduciary the information needed to reach the operator through its official process.

There is no beneficiary designation option for GitHub. This account type does not support naming a recipient the way bank or investment accounts do.

SimplyTrustSimplyTrust Editorial·

Sources

Data sourced from GitHub, Inc. (Microsoft) primary sources (8 pages reviewed). How we research.